Paper 2025/1885

Correction Fault Attack on CROSS under Unknown Bit Flips

Sönke Jendral, KTH Royal Institute of Technology
Elena Dubrova, KTH Royal Institute of Technology
Qian Guo, Lund University
Thomas Johansson, Lund University
Abstract

Recognising the need for PQC signature schemes with different size and performance trade-offs than the ML-DSA and SLH-DSA standards, in 2023 NIST launched a competition for additional signature algorithms. Among the current candidates in this competition is CROSS, a code-based scheme derived from the syndrome-decoding problem and suitable for memory-constrained devices. This paper presents a fault attack on CROSS that recovers the secret key by flipping one or more bits in the scheme’s public parity-check matrix. Unlike previous PQC fault attacks that typically rely on precisely controlled fault injections, which is often an unrealistic assumption, our approach exploits bit flips with unknown position and value, resembling the Rowhammer fault model. The attack builds upon the correction-based methodology introduced for Dilithium (Euro S&P’22; CHES’24) and exploits structural properties of CROSS to substantially relax attacker requirements. We demonstrate the attack on an ARM Cortex-M4 processor using voltage fault injection. We further show that prior work on partial key exposure attacks (CRYPTO'22) can be extended to CROSS under non-trivial erasure rates, reducing the attack complexity. The attack remains effective in the presence of memory-integrity protection mechanisms such as error-correcting codes. Finally, we propose countermeasures for hardening CROSS implementations against physical attacks.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
A minor revision of an IACR publication in TCHES 2026
DOI
10.46586/tches.v2026.i2.192-217
Keywords
Fault InjectionCROSSCode-based CryptographyPost-Quantum Digital SignaturePartial Key Exposure Attack
Contact author(s)
jendral @ kth se
dubrova @ kth se
qian guo @ eit lth se
thomas johansson @ eit lth se
History
2026-04-29: revised
2025-10-09: received
See all versions
Short URL
https://ia.cr/2025/1885
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1885,
      author = {Sönke Jendral and Elena Dubrova and Qian Guo and Thomas Johansson},
      title = {Correction Fault Attack on {CROSS} under Unknown Bit Flips},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1885},
      year = {2025},
      doi = {10.46586/tches.v2026.i2.192-217},
      url = {https://eprint.iacr.org/2025/1885}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.